36a7ae147e
The 4×64-bit reduceWide in FieldP had a bug: round 2 carry propagation could overflow past 256 bits when out[0..3] were all 0xFF...FF, silently dropping the overflow. This caused field multiplication results to be off by exactly C = 2^32 + 977, corrupting point arithmetic for specific intermediate values (e.g. ECDH with scalar n-2 on small x-coordinates). Fix: detect round-2 overflow and fold the extra bit (≡ C mod p) back in. Also fix ktlint violations in ScalarN and update documentation. https://claude.ai/code/session_01BhU63WUe9AhikZxRdw3Lpg